Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-8037

Опубликовано: 04 июн. 2026
Источник: nvd
CVSS3: 9.6
CVSS3: 9.8
EPSS Высокий

Описание

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:progress:connection_manager_for_objectscale:*:*:*:*:*:*:*:*
Версия до 7.2.63.2 (исключая)
cpe:2.3:a:progress:ecs_connection_manager:*:*:*:*:*:*:*:*
Версия до 7.2.63.2 (исключая)
cpe:2.3:o:progress:loadmaster:*:*:*:*:*:*:*:*
Версия до 7.2.54.18 (исключая)
cpe:2.3:o:progress:loadmaster:*:*:*:*:*:*:*:*
Версия от 7.2.55.0 (включая) до 7.2.63.2 (исключая)

EPSS

Процентиль: 100%
0.84793
Высокий

9.6 Critical

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 9.6
github
2 месяца назад

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

EPSS

Процентиль: 100%
0.84793
Высокий

9.6 Critical

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-77